Ctrl AI
Technology shaped
by operational experts
NewsSubject access requests

Ctrl AI launches assisted subject access request review

Teams can now take a subject access request from the first email to a reviewed disclosure bundle, with Ctrl AI proposing what to disclose and redact and a person signing off every document.

What we are launching

Ctrl AI now handles subject access requests. The workflow takes a request from the email or letter it arrives in through to a disclosure bundle and a response letter, and a member of staff reviews every document before anything is released.

Subject access requests land on HR, data protection and complaints teams that already have a day job. Across the sector we see more of them every year, and they are expensive to run. They often arrive alongside a grievance, a complaint or a claim, they ask for “all emails, notes and metadata”, and more of them are drafted with AI. Most of the cost sits in the reading.

Disputes about the responses are rising too. When a response is late, incomplete, over-redacted or not handled in line with ICO guidance, the requester complains and the original request becomes a second piece of work. Data protection complaints to the ICO rose 81% in 2025/26.

From the request to the records

The workflow starts with the request. Ctrl AI proposes who the requester is, what they have asked for, the dates and people involved and the systems likely to hold their data, drawing on the organisation’s own map of where its records live. Staff confirm that assessment before any records are added.

Request assessment for an employee subject access request: identity, scope and triage for staff to confirm before any records are added. Demonstration case.
Request assessment for an employee subject access request: identity, scope and triage for staff to confirm before any records are added. Demonstration case.

Staff then run the searches and upload what they find, in bulk. Ctrl AI reads every page, including scans and images, and flags exact duplicates, so nobody reads the same email chain six times.

Relevance and redaction, with a reason for each

Each document gets a proposal: disclose, disclose with redactions or withhold, with the reason in plain words. Whole pages can be excluded from a document, and privileged material is flagged for a decision. The guidance behind those proposals combines the ICO’s approach with the organisation’s own rules, for example on naming colleagues and other third parties.

Redaction follows the request. The requester’s own information stays in, other people’s personal data is proposed for redaction under the organisation’s own categories, and people and roles are identified consistently across the whole set of records. A separate step finds the exact text on the page, and anything it cannot locate is flagged for a person to deal with.

Records for the same request, each proposed as in scope, partly in scope or privileged, with the pages affected and its review status. Demonstration case.
Records for the same request, each proposed as in scope, partly in scope or privileged, with the pages affected and its review status. Demonstration case.

Every document signed off

Nothing leaves the platform until a member of staff has recorded a review on every document. Ctrl AI then builds the disclosure bundle, with a cover page, an index and a schedule of the pages disclosed, and drafts the response letter for staff to approve.

Every decision is kept with its reason, and that matters in both directions. A missed redaction is a data breach, and the High Court in Ashley v HMRC (2025) showed that heavy redaction with the context stripped out can also fail. A team that can show why each page was disclosed, redacted or withheld is in a far stronger position if the requester complains to the ICO.

Why we built it this way

Most subject access work is the same set of steps, repeated under a statutory deadline. That makes it a good fit for the approach behind the rest of Ctrl AI: define each task, test it, and keep a person in charge of the decision. Reviewers start every page from a reasoned proposal instead of a blank screen, and the organisation keeps a full record of who decided what.

The workflow is configured for employee, consumer and housing requests, and for FOI, and runs in the same platform as complaints and employment cases. Client data is stored in the UK, Ctrl AI is ISO 27001 certified, and we never use client data to train AI models. Teams can see it work on a sample request using test data.

All news and insights

Discuss the work your team needs to do

Review a relevant workflow, the platform’s capabilities and the controls your organisation needs.

Talk to Ctrl AI